XNU suffers from a race condition leading to a use-after-free between the NFSSVC_NFSD command and an upcall worker thread.
7ffbd2f24181807ee212967faac09584f8f2b2db84a64cd1af883cc860d8e6a6
A dangling pointer vulnerability is present in WebRTC's PacketRouter due to an SDP SIM group SSRC from one track (e.g., video) colliding with an existing SSRC from a different track (e.g., audio). This inconsistency between the send_modules_map_ and the send_modules_list_ can lead to a use after free.
426fe7fd9743d7c7d9ba2167f870968aaad57ccdefafb8bca89ee26333cad8be
XNU NFSSVC suffers from root check bypass and use-after-free vulnerabilities due to insufficient locking in upcall worker threads.
dd5db6e40185f5ad1603a814730e94b92ca2cfb3086268f82937050b80986d44
XNU has a race condition leading to use-after-free between the NFSSVC_NFSD command and an upcall worker thread.
558e5741f83f094c1d723a718badc745f6249cf15cef1cd4a50ca6eee80f69f8
XNU suffers from a flow divert race condition use-after-free vulnerability.
18168cefa7044ee89ba183a692734419daa60890808dbb1d62407aa2c4c7f70c
Android NFC suffers from a type confusion vulnerability due to a race condition during a tag type change.
08fb25b7d8382b17929eba513aa143b8803817300bc39c7324b97c461ec1858e
Android NFC suffers from a type confusion vulnerability in nfa_rw_sys_disable.
7a12df472496a0e739a7d1979be71fa941ec278836bae496a8bfd948c0899ca3
Android suffers from memory disclosure, out-of-bounds write, and double-free vulnerabilities in NFC's Felica tag handling.
4db4d57382e328731ad76c3c97332ef31a2266fa29ee8223cb6679b86c5e37c6
Android suffers from an out-of-bounds write in the NFC stack when handling MIFARE Classic TLVs.
95f7586d9c9572c817ae465d9365cac1a950277dfa2d9ddeb3aefcc41ac59f17
XNU suffers from a use-after-free vulnerability in tcp_input.
25701e8eca80114c8645a6f7aaac15b7712ce7c0be471ffb9169c8dccc28d609
XNU suffers from a remote mbuf double-free vulnerability in ip6_notify_pmtu.
f6d1a4b89651c23358fcd0d3e842c59d4bca332db3139711e5ce8ff69f02574d
XNU suffers from a use-after-free vulnerability due to a stale pointer left by in6_pcbdetach.
bef8d392354ac6f32aad2cc335619acb48b545689c0c72e1a05e0b745d672e69
XNU suffers from a wild-read (and possible corruption) due to bad cast in stf_ioctl.
470329e1920caa904f96f74e15916983bba7d0ee716d7e801ef03849690a1b83